CVE-2018-17879

Scores

EPSS

0.622medium62.2%
0%20%40%60%80%100%

Percentile: 62.2%

CVSS

9.8critical3.x
0246810

CVSS Score: 9.8/10

All CVSS Scores

CVSS 3.x
9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

An issue was discovered on certain ABUS TVIP cameras. The CGI scripts allow remote attackers to execute code via system() as root. There are several injection points in various scripts.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-78

Vulnerable Software (47)

Type: Configuration

Vendor: *

Product: tvip_10000_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:abus:tvip_10000_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: tvip_10001_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:abus:tvip_10001_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: tvip_10005_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:abus:tvip_10005_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: tvip_10005a_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:abus:tvip_10005a_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "O...

Source: nvd

Type: Configuration

Vendor: *

Product: tvip_10005b_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:abus:tvip_10005b_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "O...

Source: nvd

Type: Configuration

Vendor: *

Product: tvip_10050_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:abus:tvip_10050_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: tvip_10051_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:abus:tvip_10051_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: tvip_10055a_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:abus:tvip_10055a_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "O...

Source: nvd

Type: Configuration

Vendor: *

Product: tvip_10055b_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:abus:tvip_10055b_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "O...

Source: nvd

Type: Configuration

Vendor: *

Product: tvip_10500_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:abus:tvip_10500_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: tvip_10550_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:abus:tvip_10550_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: tvip_11000_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:abus:tvip_11000_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: tvip_11050_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:abus:tvip_11050_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: tvip_11500_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:abus:tvip_11500_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: tvip_11501_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:abus:tvip_11501_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: tvip_11502_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:abus:tvip_11502_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: tvip_11550_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:abus:tvip_11550_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: tvip_11551_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:abus:tvip_11551_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: tvip_11552_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:abus:tvip_11552_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd

Type: Configuration

Vendor: *

Product: tvip_20000_firmware

Operating System: * * *

Trait:
{  "children": [    {      "cpe_match": [        {          "cpe23uri": "cpe:2.3:o:abus:tvip_20000_firmware:-:*:*:*:*:*:*:*",          "vulnerable": true        }      ],      "operator": "OR...

Source: nvd